>_devtools

otpauth:// URI Parser, Builder & QR Code

Parse an otpauth:// URI into issuer, account, and secret, or build one and get a QR code for an authenticator app. The secret never leaves your browser.

What this does

An otpauth:// URI is what a two-factor setup QR code contains. This page parses one into its parts (type, issuer, account, secret, algorithm, digits, period or counter), or builds one from a form, and draws a QR code you can scan with an authenticator app or download as SVG or PNG.

Format

otpauth://TYPE/LABEL?secret=BASE32&issuer=ISSUER, where TYPE istotp or hotp and LABEL is Issuer:account. Optional parameters are algorithm (SHA1, SHA256, SHA512), digits (6, 7, or 8), period for TOTP (default 30), and a required counter for HOTP. The page warns when the label issuer and the issuer parameter disagree, and when you use settings that Google Authenticator and several other apps silently ignore.

Errors

Parsing reports a specific reason: a wrong scheme, an unknown type, a missing or non-Base32 secret, out-of-range digits, a bad period, a missing HOTP counter, or an unsupported algorithm.

Example

"Load example" in Parse mode fills a typical TOTP URI. Use "Edit in builder" to change a field, then scan the new QR code.

Privacy

The QR code contains the secret and is drawn entirely in your browser with no network request. Nothing is stored or placed in the URL. Treat the QR code and any download of it like a password.